Junglewise Threat Intelligence

CVE-2026-71120: Oracle Hyperion Financial Management denial of service in security component

CVE-2026-71120 · Severity: medium · CVSS 5.3 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial consolidation and planning tool used by enterprises to manage corporate accounting and budgeting. A low-privileged, network-accessible attacker can trigger a denial of service condition that causes the application to hang or crash repeatedly, disrupting financial operations and reporting capabilities until the system is restarted.

Technical details

This is a denial-of-service vulnerability in Oracle Hyperion Financial Management's security component affecting version 11.2.25.0.000. The vulnerability is difficult to exploit and requires low-privilege credentials plus network access over HTTP. The attack vector enables an authenticated attacker to cause the application to hang or repeatedly crash, resulting in complete unavailability of the financial management system. No details on the specific root cause or vulnerable code path are currently available.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats